The new COVID-19 tracker is under the auspices of Minister Stuart Robert … What could go wrong? … Problems with the proposed app … Prying police forbidden … How it works … Hacking is inevitable … A decentralised model would be less of a threat to privacy … Centralised server would be a vehicle for mass surveillance … The key issues clarified by Janek Drevikovsky
The mobile phone app is intended to speed up the process of “contact-tracing” by registering every time two users come into close proximity.
The app will collect personal data, initially under encryption. But if a user contracts COVID-19, the app will give health authorities a ready list of their close-contacts.
That means there will be a decryption key. And where there’s a decryption key, data can be hacked, or misused, or stolen.
The latest reports suggest the app will launch in the next week or two. The Prime Minister has forsworn making the app compulsory, but deep suspicions remain.
Over 63 per cent of Australians say they would be concerned with their data security if the app was on their phone, according to an Essential poll. Only 35 per cent were “confident” the government would not misuse the information.
And only 38 per cent said they would actually download the software.
Privacy concerns are rearing their head like never before. So can we trust the app won’t breach our privacy? What legal framework exists to ensure it will not? Or are we all getting worked up over nothing?
“The Privacy Act would require the government to obtain individuals’ consent for the collection and use of their health information,” Dr Kemp told the GLJ.
The Act also requires the government to provide proper notice of the data that’s being collected and the purpose for which it’s being collected when users initially download the app.”
To conform with the Act, the government must make sure the data is used for limited purposes, Dr Kemp said.
“Decrypted data logs … should not be kept for purposes other than the current coronavirus crisis. They should be deleted by the end of the crisis at the latest.”
Users should also be able to withdraw consent if they wish to stop using the app, Dr Kemp said, in which case all their data should be deleted.
“But the government has not said it’s including that right in its privacy protections at this stage.”
The Commonwealth’s maze of national security laws might also affect how the app works. Under the Telecommunications (Assistance and Access) Amendment Act 2018, state and federal authorities can force telcos and tech companies to decrypt their customers’ data, if necessary to investigate a serious crime. No warrant is needed.
There are also laws allowing police to access metadata and to apply for warrants to hack and monitor people’s devices, no matter the seriousness of the alleged crime.
In theory, law enforcement could use these laws to get their hands on data gathered by the app. That could spell trouble for the government’s promise that the information will only be used for contact tracing.
Faced with this problem Attorney General Christian Porter is promising promised to introduce regulations to restrict use of the app.
“Specific regulatory action will be taken to prevent such access for law enforcement agencies at both the Commonwealth and state/territory level,” he said in a statement.
“Further details of this aspect of the app will be provided when it is officially launched,” Porter added.
Privacy protections could also be built into the app’s terms and conditions, forming a contract between users and the government.
That’s according to Professor Barbara McDonald of the University of Sydney, who led the ALRC’s investigation into serious invasions of privacy.
“Perhaps the [app’s] guidelines need to say that the government accepts it receives this information on a confidential basis for the purposes it sets out,” Professor McDonald told Justinian.
“And so if you reveal your identity on the basis of that agreement, then I would think you have so there would be an obligation of confidence.”
Presumably there’s some form of contract there. The provider is bound by those terms and conditions just as much as the user.”
Dr Kemp agreed that the app needed a “clear, simple, accurate privacy policy.”
“It should set out strict limits on the data that will be collected and who can access that data [with] strictly limited pandemic-fighting purposes for which that data can be used.”
At the same time, Australians should not lose sight of important public health goals, according to Professor McDonald.
“Privacy is relative. It often has to give way to greater public interest … It’s always going to be a balance.
My own view is that, if it’s a temporary thing, if it will be effective to alert people they have been close to somebody with the virus, then I’ll be signing up.”
How the app affects its users’ privacy will come down to the nitty-gritty.
“It’s a matter of design,” Professor McDonald said. “All these things are programmes and programmes depend on human input.”
Instead, all phones carrying the app will emit a bluetooth signal. Using this signal, two phones will register “close contact” if they spend 15 minutes within a 1.5 meter radius of one another.
Upon recording a close contact, the phones will exchange encrypted information, carrying the name, postcode, phone number and age range of the user.
The encrypted data will be stored locally on users’ devices. Any unused data will be automatically deleted after 21 days. Nothing will be sent to the authorities – unless a user tests positive to the coronavirus.
From there, it will be made available to state and territory contact tracer teams. Commonwealth agencies will have no access to the data.
The model has significant problems, according to Dr Kemp. One is whether the data to be gathered is really needed for “alerting people when they’ve been in contact with a person who’s tested positive”.
“For example,” Dr Kemp said, “why is it necessary to have our age range to do that?”
There are also concerns about the app’s centralised model of data storage, which involves information being sent to a central government server.
A decentralised model, in contrast, has no government involvement. Instead, when a user tells the app they are sick, the software sends a notification directly to every registered close-contact. The notification simply says to get tested and self-isolate. No personal data is ever decrypted.
According to Dr Kemp, a decentralised model would be safer.
“No app users could work out the identity of the contacts on that list,” she said. And there would be no risk of a cyber attack compromising all the data at once.
Do not download the contact tracing app set up by @StuartRobertMP. This govt has a TERRIBLE track record on data protection, particularly when it comes to our health data, and this app comes with very real privacy concerns that Australians should be aware of #AusPol #COVID19Aus
— Senator Jordon Steele-John 🌏🔥 (@Jordonsteele) April 22, 2020
Under a centralised model, things could go very wrong.
Hacking is a near-certainty, according to Professor Richard Buckland of UNSW.
“Everything can be hacked,” he told the Sydney Morning Herald. “The [United States’] National Security Agency and Facebook are both far better funded than we are – and they’ve both been breached.”
A centralised server might also facilitate mass surveillance.
Researchers at the University of Melbourne analysed a Singaporean app, TraceTogether, which is the model for the Australian app.
As more users became sick, more uploaded their data to the central store, which was soon overflowing in decrypted or easily decryptable personal data.
Eventually, the central authority might have enough data to engage in “mass surveillance”.
One of the researchers, Professor Dali Kaafar of the Optus Macquarie Cyber Security Hub, explained how monitoring might become a reality.
Speaking to the SBS, he said the central authority would know who spent time with whom and for how long.
“The only information we don’t necessarily have is the location. We might not know where they met, but we know that they did meet,” Professor Kaafar said.
With data from thousands or hundreds of thousands of people, it would be easy to build a “social graph” for individual app users, allowing for close monitoring.
The Australian app will not be identical to TraceTogether, so protections may be built in to prevent surveillance.
Ultimately, failing to clarify privacy issues will only backfire, according to Professor McDonald.
The My Health scheme was an example of what could go wrong, she said. After a decade of development, the online health record system was found to be signing patients up without their consent.
The scheme faced pronounced backlash and now suffers from underuse, with many privacy-conscious Australians opting out.
“One of the great problems about [My Health] was that the government wasn’t upfront at the beginning about who it was going to give the information to,” Professor McDonald said.
“Once people think it can be used for other purposes, they’re going to be very reluctant [to sign up].”
